summaryrefslogtreecommitdiff
path: root/lib/web/note
diff options
context:
space:
mode:
authorErik Michelson2021-03-29 23:00:34 +0200
committerErik Michelson2021-03-29 23:00:34 +0200
commit124b06425214921c30a88e44a139b1cc8ca15b45 (patch)
treeaa26e15cae2f48aa4651d54a2a21793e8ddd0a9d /lib/web/note
parent6531ea1a2144804677f6832646f18117b1e555a2 (diff)
Check for existing notes on POST and dont override them
Previously one could override notes in FreeURL-mode by sending multiple POST requests to the /new/<alias> endpoint. This commit adds a check for an already existing note with the requested alias and returns a HTTP 409 Conflict error in case that happens. Signed-off-by: Erik Michelson <opensource@erik.michelson.eu>
Diffstat (limited to '')
-rw-r--r--lib/web/note/util.js15
1 files changed, 14 insertions, 1 deletions
diff --git a/lib/web/note/util.js b/lib/web/note/util.js
index effeb41c..dbca5d8e 100644
--- a/lib/web/note/util.js
+++ b/lib/web/note/util.js
@@ -46,7 +46,7 @@ exports.checkViewPermission = function (req, note) {
}
}
-exports.newNote = function (req, res, body) {
+exports.newNote = async function (req, res, body) {
let owner = null
const noteId = req.params.noteId ? req.params.noteId : null
if (req.isAuthenticated()) {
@@ -60,6 +60,19 @@ exports.newNote = function (req, res, body) {
} else {
return req.method === 'POST' ? errors.errorForbidden(res) : errors.errorNotFound(res)
}
+ try {
+ const count = await models.Note.count({
+ where: {
+ alias: req.alias
+ }
+ })
+ if (count > 0) {
+ return errors.errorConflict(res)
+ }
+ } catch (err) {
+ logger.error(err)
+ return errors.errorInternalError(res)
+ }
}
models.Note.create({
ownerId: owner,